SomNOG9 Workshops: Cybersecurity

→ Africa/Mogadishu
SNU KM4 Campus

SNU KM4 Campus

Mogadishu, Somalia
Ibar O. Ibrahim (SomaliREN)
Description

Track Description

The Cybersecurity Track introduces participants to the core knowledge and practical skills required to begin working in cybersecurity. Designed primarily for final-year students, fresh graduates and early-career ICT professionals, the track combines foundational concepts with intensive hands-on practice. Participants will work through a progressive learning journey covering cybersecurity principles, networking for security, reconnaissance, vulnerability assessment, web security, controlled exploitation, system hardening, security monitoring, incident response and basic digital forensics. Approximately 60-70% of the track is practical, using an isolated lab environment and tools such as Nmap, Wireshark, OWASP Juice Shop, Linux security utilities and Wazuh. The curriculum is benchmarked against foundational competencies found in internationally recognized entry-level certifications such as ISC2 Certified in Cybersecurity (CC) and Cisco CCST Cybersecurity, while remaining vendor-neutral and focused on real operational skills.

Who Should Attend?

This track is designed for final-year university students, fresh graduates and early-career ICT professionals who want to build a strong practical foundation in cybersecurity. Prior hands-on cybersecurity experience is not required, although basic familiarity with computers and networking will be helpful.

Workshop Approach

The track is highly practical, with approximately 60-70% of learning time dedicated to demonstrations, hands-on labs and team exercises. All security testing activities are conducted only within the authorized SomNOG lab environment

Contact Us
    • 09:30 → 10:00
      Opening, Track Orientation, Ethics, Lab Rules & Pre-Assessment 30m
      Speaker: Eng Bille
    • 10:00 → 10:30
      Cybersecurity Foundations: CIA, Risk, Controls, IAM & Least Privilege 30m
      Speaker: Eng Liban
    • 10:30 → 11:00
      Networking for Cybersecurity: TCP/IP, DNS, HTTP/S, SSH, ICMP, Firewalls, IPv4/IPv6 30m
      Speaker: Eng Abdulkadir
    • 11:00 → 11:30
      Morning Break 30m
    • 11:30 → 12:00
      Lab 1: Network & Service Discovery 30m
      Speaker: Eng Abdulkadir
    • 12:00 → 12:30
      Linux Fundamentals for cybersecurity 30m
      Speaker: Eng Ismail
    • 12:30 → 13:30
      Lunch 1h
    • 13:30 → 14:00
      Mitra Attack, Kill chain, unified Kill chain, diamond models, pyramid of pain, 30m
      Speaker: Eng Meymun
    • 14:00 → 14:40
      Threats, Vulnerabilities, Attack Surface & Introductory Adversary Workflow 40m
      Speaker: Eng Meymun
    • 14:45 → 15:00
      Cybersecurity Lab Environment preparations 15m
    • 15:00 → 15:30
      Why a SOC matters · today's threat landscape (who attacks, how they get in) 30m
      Speaker: Eng Liban
    • 15:30 → 16:00
      Afternoon Break 30m
    • 16:00 → 16:50
      SOC operations, tiers, the incident lifecycle, the analyst's skills, Core SOC technologies, SIEM, EDR/XDR, SOAR; log sources & telemetry. 50m
      Speaker: Eng Bashir
    • 16:50 → 17:00
      Reading an alert · True vs False Positive · KQL basics · the escalation ladder 10m
      Speaker: Eng Bashir
    • 08:00 → 08:30
      Day 1 Review & Short Quiz 30m
    • 08:30 → 09:00
      Footprinting and Reconnaissance 30m
      Speaker: ENG Liiban
    • 09:00 → 10:00
      Lab 2: Footprinting and Reconnaissance 1h
      Speaker: All Team
    • 10:00 → 10:30
      Morning Break 30m
    • 10:30 → 10:50
      Scanning Networks and Enumeration 20m
      Speaker: Eng Liiban
    • 10:50 → 11:30
      Lab 3: Scanning Networks and Enumeration 40m
      Speaker: All Team
    • 11:30 → 11:50
      Vulnerabilities, CVE, CVSS & Vulnerability Management 20m
      Speaker: Liban
    • 11:50 → 12:30
      Lab 4: exploit some local machine with Metasploit framework 40m
      Speaker: Eng Abdulkadir
    • 12:30 → 13:30
      Lunch 1h
    • 13:30 → 14:00
      Web Application Security & Selected OWASP Concepts 30m
      Speaker: Eng Ismail
    • 14:00 → 15:30
      Lab 5: Web Application Security 1h 30m
      Speaker: Eng Ismail
    • 15:00 → 15:30
      Navigating the SIEM · running KQL · triage workflow · correlating events · separating signal from noise. 30m
      Speaker: Eng Bashir
    • 15:30 → 16:00
      Afternoon Break 30m
    • 16:00 → 16:50
      Lab 6: SMB/RDP Brute force, from an internal and external attackers 50m
      Speaker: Eng Bashir
    • 16:50 → 17:00
      Lab 7 : Network reconnaissance / port scan, Malicious PowerShell, LOLBin download and Multi-step attack mapped to ATT&CK (recon → brute → credential access) 10m
    • 08:00 → 08:20
      Day 2 Review 20m
    • 08:20 → 09:00
      Web application penetration testing concepts 40m
      Speaker: Eng Ismail
    • 09:10 → 10:00
      Lab 8: preform real time web application penetration testing 50m
      Speaker: All Team
    • 10:00 → 10:30
      Morning Break 30m
    • 10:30 → 12:30
      CTF competitions. “Should be prepared”` 2h
      Speaker: Ismail , Liban
    • 12:30 → 13:30
      Lunch 1h
    • 13:30 → 14:30
      Risk and risk mitigation strategies 1h
      Speaker: Eng Liban
    • 14:30 → 15:30
      endpoint attack analysis · defense-evasion & ransomware behavior · cloud control-plane attacks · threat-intel enrichment · containment & reporting 1h
      Speaker: Eng Bashir
    • 15:30 → 16:00
      Afternoon Break 30m
    • 16:45 → 17:00
      Post-Assessment, Career & Certification Roadmap, Closing 15m